T08 · Insecure Dependencies
- Location
references/review-closeout.md:7- Finding
Unpinned Third-Party Review Tools May Execute Mutable External Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:57-61, 101, 105;references/review-closeout.md:7-9, 34-52
Vulnerability Type: Supply-chain exposure through unpinned third-party tools
Risk Level: MediumVulnerable Code Snippets
SKILL.md:57-61:text AutoReview is the OpenClaw agent-skills structured code review helper from https://github.com/openclaw/agent-skills/tree/main/skills/autoreview, credited to OpenClaw agent-skills. ClawPatch is the npm `clawpatch` automated code review/fix CLI from https://www.npmjs.com/package/clawpatch. npm metadata has listed maintainer `steipete`; refresh package metadata before installing and treat the refreshed metadata as current truth.SKILL.md:101-105:text 8. For substantial or unattended builds, read `references/unattended-orchestration.md` and use `$subagent-orchestrator` or available multi-agent tooling when present. Child agents should use the existing project folder and `context.md`. 9. Build the smallest complete version with a real first interaction. 10. If visual assets, sprites, icons, generated art, or audio matter, copy `assets/art-asset-plan-template.md` into the project as `assets/asset-plan.md` and use it. 11. Verify with the strongest local proof available: run/build/test, browser check, playtest, visual inspection, CLI sample, or whatever fits the artifact. 12. If AutoReview or ClawPatch were opted in, read `references/review-closeout.md`, run the chosen review/fix loop after normal proof, then rerun proof.references/review-closeout.md:7-9:text - AutoReview: structured code review helper from OpenClaw agent-skills, https://github.com/openclaw/agent-skills/tree/main/skills/autoreview, credited to OpenClaw agent-skills. - ClawPatch: npm `clawpatch` automated code review/fix CLI, https://www.npmjs.com/package/clawpatch. npm metadata has listed maintainer `steipete`; refresh npm metadata before install and use the refresh ...[truncated 3226 chars]- Remediation
View remediation
Remediation Suggestions
- Pin npm tools to an exact audited version rather than resolving the latest release.
- Pin GitHub-hosted helpers to an immutable commit SHA instead of a mutable branch or directory URL.
- Record and verify package integrity hashes and registry provenance before installation.
- Review downloaded package contents and installation scripts before first execution.
- Disable npm lifecycle scripts where the tool can operate without them.
- Run third-party review tools in an operating-system sandbox or container with:
- only the generated project mounted writable;
- unrelated local paths unavailable;
- secrets and sensitive environment variables removed;
- network access disabled unless demonstrably required;
- strict process, time, and resource limits.
- Prefer review-only operation. Apply proposed changes through the main agent after independently inspecting each finding and patch.
- Document approved versions and require a new security review before updating them.
